Chrome Web Store
2Versions
1Code reviewed

Caution required

Suspicious in code review (v1.0.0)

Our reviewer found behaviour consistent with malware in version 1.0.0, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Open in Microsoft Edge, used by 10,000 people, is rated caution by Extension Auditor. Our code review reported 4 findings (1 critical, 2 high, 1 medium), led by privilege escalation. It comes from a trusted publisher and was last updated in September 2022.

Key findings

  • critical· privilege escalation —The native messaging payload includes a complete script string that calls require('child_process').spawn with caller-controlled arguments, and declares 'permissions: [child_process]'. This pattern is characteristic of a native messaging host that acts as a code evaluator — the script field is passed to be eval'd, not ignored. Any future extension update (or a malicious native host update from) could change the script payload to execute arbitrary commands with full OS privileges, since native messaging hosts run outside the browser sandbox.
  • high· other —The bundled manifest declares manifest_version 2, while the published CWS listing reports manifest_version 3. This mismatch means the extension actually installed on user devices uses MV2 (which permits persistent background pages and broader APIs), while the CWS listing presents the safer MV3 profile to reviewers — a common technique to pass CWS review with a more permissive version.
  • high· other —The options page, shipped inside an extension branded as 'Open in Microsoft Edge', explicitly instructs users to enter the path to Tor Browser and pre-fills a Tor Browser path as the example. This is direct evidence that the extension is a template reused from an 'Open with Tor' extension without proper rebrand — the branding deception is intentional, not accidental.
  • medium· other —The 'How to use' link in the popup for this 'Open in Microsoft Edge' extension directs users to — the Tor browser companion site from the same publisher network. This confirms the extension is a renamed copy of a Tor-opener extension distributed under a false Microsoft Edge identity to attract installs from users who trust the Edge brand.

The extension presents as 'Open in Microsoft Edge' but the source code is a poorly-rebranded copy of an 'Open with Tor' extension from — the options page instructs users to enter a 'path for Tor browser', is titled 'Open with VLC', names its menu item 'Open with PowerPoint', and links to. More critically, sends a hardcoded script string (including require('child_process').spawn) to a native host at net.freefinancetools.openfrombrowser, a design pattern that implies the native host is a evaluator executing arbitrary code — far beyond what is needed to simply open a URL. The permhash cluster has 44% malicious peers and the publisher has 33% malicious rate across their portfolio, corroborating the ML and third-party signals.

Open in Microsoft Edge

Open in Microsoft Edge Chrome extension security report

ID: akkeflfepdogekcemgkidllneichjhce

Supported Languages

🇧🇬Bulgarian
🇪🇸Catalan
🇭🇷Croatian
🇨🇿Czech
🇩🇰Danish
🇳🇱Dutch
🇺🇸English
🇪🇪Estonian
🇵🇭Filipino
🇫🇮Finnish
🇩🇪German
🇬🇷Greek
🇮🇱Hebrew
🇮🇳Hindi
🇭🇺Hungarian
🇮🇹Italian
🇯🇵Japanese
🇰🇷Korean
🇱🇻Latvian
🇱🇹Lithuanian
🇵🇱Polish
🇷🇴Romanian
🇷🇺Russian
🇸🇮Slovenian
🇪🇸Spanish
🇸🇪Swedish
🇹🇭Thai
🇹🇷Turkish
🇺🇦Ukrainian
🇻🇳Vietnamese

Extension Info & Metadata

Status
Active
Version
3.0.0
Size
0.30 MB
Rating
3.5/5
Reviews
332
Users
10,000
Type
Extension
Updated
Sep 16, 2022
Category
Workflow & planning
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
27extensions
8 no longer listed

Publisher Contextual Analysis

Trusted
Author
Thomas David
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
27
Active
18
Obsolete
8
Listed
27
Unlisted
0
Users
43,984

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Easily open desired links in Microsoft Edge Browser

Read the publisher’s full description

Easily open website links in Microsoft Edge Open a website using Microsoft Edge now. Want to open a website using your favorite browser software Microsoft Edge? You can do so now after you install our software extension. To begin using our software extension, here are the steps you need to do. Ensure you have Edge installed on your computer. Install our software extension Once you install our software, please refresh all your existing Tabs/close browser and restart browser to let the extension load. Choose the link you wish to open with Edge via the right click context menu button. Its that simple, just use the right click context menu to choose Edge when you want to open a website. Please note this extension was NOT made by Microsoft. It was made by an external third party developer.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
7

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
1.0.0
Latest
0.36 MBCaution0
d52d8c3cb6114a174f292514909bfb8fa0f59eac51f0ff6c53c78f754cdadc71
3.0.0
0.30 MBNot scanned—
d52d8c3cb6114a174f292514909bfb8fa0f59eac51f0ff6c53c78f754cdadc71
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from Thomas David

Popular in Workflow & Planning